Key Takeaways
- Immediately secure all digital evidence—including EHR audit logs, billing metadata, and internal communications—under a litigation hold that complies with Federal Rule of Civil Procedure 26(b)(2)(B) and the E-Discovery amendments to the Federal Rules of Civil Procedure.
- Conduct a privileged internal investigation under the attorney-client privilege and work-product doctrine, as codified in Rule 502 of the Federal Rules of Evidence, before any federal agent or relator’s counsel requests documents.
- Review and preserve all Stark Law and Anti-Kickback Statute compliance documentation—specifically 42 U.S.C. § 1320a-7b(b) and 42 U.S.C. § 1395nn—because the government’s statistical sampling model under the False Claims Act (31 U.S.C. § 3729) will extrapolate liability from a single flawed referral.
- Engage a federal criminal defense attorney with experience in health-care fraud prosecutions under the Health Care Fraud Statute (18 U.S.C. § 1347) before you speak to any investigator, corporate compliance officer, or whistleblower’s counsel.
1. Execute a Forensic Preservation Hold on All Electronic Health Records and Billing Systems—Before the Grand Jury Subpoena Arrives
In my 25 years as a federal prosecutor, I saw more health-care defendants lose their cases before the first indictment was unsealed because they failed to preserve evidence in its native format. When the government issues a grand jury subpoena under Rule 17(c) of the Federal Rules of Criminal Procedure, or when a qui tam relator files a complaint under seal pursuant to 31 U.S.C. § 3730(b)(2), the clock starts ticking on your duty to preserve. You cannot wait for a formal litigation hold letter from the Department of Justice. You must act now to freeze all electronic health record (EHR) systems, including audit trails that show who accessed a patient’s chart, when, and what changes were made. The EHR metadata—specifically the “date-time stamp” and “user ID” fields—are often the single most damning piece of evidence in a health-care fraud prosecution because they reveal patterns of upcoding or phantom billing.
Your IT department must immediately disable any automatic deletion policies that purge records older than 90 days, as many EHR platforms do by default. I have personally cross-examined defense experts who tried to explain away missing audit logs, and juries simply do not believe that a sophisticated health-care organization “accidentally” lost the very records the government subpoenaed. You must also preserve all internal communications—including text messages, Slack channels, and encrypted messaging apps—that relate to coding decisions, referral patterns, or financial arrangements with referring physicians. The Federal Rules of Civil Procedure, specifically Rule 26(b)(2)(B), allow the court to sanction a party for failing to preserve electronically stored information that should have been preserved in the anticipation of litigation. Those sanctions can include an adverse inference instruction, which is often case-dispositive.
Do not rely on your general counsel or compliance officer to handle this alone. They are not criminal defense attorneys, and they may inadvertently waive privilege by discussing the investigation with third parties. I recommend you retain a federal criminal defense lawyer who understands the technical requirements of forensic preservation under the Federal Rules of Evidence 502(d) and 502(e) clawback provisions. We will draft a written litigation hold notice that specifically identifies the categories of ESI that must be preserved, including backup tapes, server logs, and cloud-based data repositories. We will also coordinate with a certified e-discovery vendor who can image hard drives and create forensic copies without altering metadata. This is not a task for your in-house IT staff, who may inadvertently spoliate evidence by running standard maintenance protocols.
Finally, understand that the government’s statistical sampling model—authorized under 31 U.S.C. § 3730(e)(1) and upheld in cases like United States ex rel. Martin v. Life Care Centers of America—allows the DOJ to extrapolate liability from a small sample of claims. If you lose even a single day’s worth of billing records, the government will argue that the missing data supports an inference of fraud. I have seen defendants face treble damages under the False Claims Act, plus civil monetary penalties of $11,000 to $22,000 per false claim, simply because they could not produce the underlying documentation for a 90-day period. The preservation order must be in writing, acknowledged by every employee who touches patient data, and audited weekly. Failure to do so is professional malpractice in the criminal defense context.
2. Conduct a Privileged Internal Investigation Into All Financial Relationships With Referral Sources—Stark Law and AKS Compliance Is Not Optional
Every health-care defendant I have represented who received a target letter from the DOJ’s Fraud Section had one thing in common: they had an undocumented or loosely documented financial relationship with a referring physician. The Stark Law, codified at 42 U.S.C. § 1395nn, prohibits a physician from referring Medicare patients to an entity with which the physician has a financial relationship, unless an exception applies. The Anti-Kickback Statute, 42 U.S.C. § 1320a-7b(b), makes it a felony to knowingly and willfully offer, pay, solicit, or receive remuneration to induce referrals of items or services covered by a federal health-care program. These statutes are strict liability in many respects, and the government does not need to prove that you intended to violate the law—only that you knew the payments were made and that referrals occurred.
You must immediately gather every contract, lease, employment agreement, medical directorship agreement, and per-click or per-patient payment arrangement with any physician or entity that refers patients to your practice or facility. I advise my clients to create a spreadsheet that lists each referral source, the total compensation paid over the last five years, the fair market value of the services provided, and the specific Stark exception or AKS safe harbor that applies. The safe harbors are found at 42 C.F.R. § 1001.952, and they include protections for personal services agreements, space and equipment leases, and managed care arrangements, but only if the agreements are in writing, signed, and for a term of at least one year. If any of your arrangements lack a signed writing, you have a significant exposure that must be addressed immediately.
This internal investigation must be conducted under the attorney-client privilege and the work-product doctrine, as codified in Federal Rule of Evidence 502. That means you cannot share the results with your compliance committee, your board of directors, or your outside auditors unless they are functioning as your lawyers’ agents. I have seen health-care executives inadvertently waive privilege by forwarding a privileged internal investigation report to their billing manager or their CPA. Once privilege is waived, the government can compel production of the entire report, including any admissions or corrective actions you identified. We will structure the investigation so that the attorney directs the work, the attorney selects the reviewers, and the attorney receives the final report. This is the only way to ensure that your self-assessment does not become the government’s roadmap to an indictment.
One critical step that many defendants overlook is reviewing the “commercial reasonableness” of each financial arrangement. Even if a contract satisfies a Stark exception on its face, the government will argue that the compensation was not at fair market value or that the arrangement was not commercially reasonable. The DOJ’s Health Care Fraud Unit uses data analytics to compare your compensation to industry benchmarks published by organizations like MGMA or SullivanCotter. If your payments to referring physicians are in the 90th percentile without a legitimate business justification, you have a red flag that will almost certainly trigger a subpoena. We will work with a health-care valuation expert who can provide a retrospective fair market value analysis, but that analysis must be done under privilege and with the explicit understanding that it is prepared in anticipation of litigation.
3. Identify and Neutralize All Whistleblower and Relator Threats Before They File a Complaint Under Seal
The False Claims Act’s qui tam provisions, found at 31 U.S.C. § 3730(b), allow private individuals—often disgruntled employees, former billing staff, or competing providers—to file a lawsuit on behalf of the government and receive 15 to 30 percent of the recovery. In my experience as a prosecutor, the most dangerous whistleblower is not the one who has already filed a complaint; it is the one who is still inside your organization, quietly collecting documents and building a case. You must immediately identify any employee who has recently raised concerns about billing practices, coding accuracy, or financial arrangements, and you must do so without violating the whistleblower’s rights under the False Claims Act’s anti-retaliation provision at 31 U.S.C. § 3730(h). That section prohibits any adverse employment action against an employee who “lawfully acts in furtherance of an action under this section.”
I recommend that you conduct a confidential interview—again, under attorney-client privilege—with each employee who has expressed concerns about compliance. Do not terminate or discipline any employee who has raised a compliance issue, even if you believe the concern is unfounded. The Department of Labor and the DOJ have taken an increasingly aggressive stance on retaliation claims, and a whistleblower who is fired can bring a separate lawsuit for reinstatement, back pay, and double damages. Instead, we will work with you to document the employee’s concerns, investigate them thoroughly, and implement corrective actions if necessary. If the employee’s concern is valid, you have an opportunity to self-disclose to the DOJ under the Health Care Fraud Self-Disclosure Protocol, which may result in a non-prosecution agreement or a reduced penalty under the U.S. Sentencing Guidelines.
You must also review all non-disclosure agreements (NDAs) that your employees have signed. The DOJ has made it clear that NDAs that prevent employees from reporting fraud to the government are unenforceable and may themselves constitute an independent violation of the False Claims Act. In fact, the Department of Justice’s Civil Fraud Section has issued guidance stating that it will consider the existence of overly restrictive NDAs as a factor in determining whether to pursue a case. We will revise your NDAs to include a carve-out that explicitly permits employees to communicate with government investigators without prior authorization. This is not a sign of weakness; it is a strategic move that removes a potential weapon from a future relator’s arsenal.
Finally, if you suspect that a whistleblower has already approached the government, you must act with extreme caution. The False Claims Act allows the government to intervene in a qui tam action within 60 days of the complaint being filed, and the complaint remains under seal during that period. You will not know that a case has been filed until the government unseals it, which could be months or even years later. In the meantime, you should preserve all evidence as described in Section 1, and you should prepare a “proffer strategy” in case the government invites you to a “queen for a day” meeting. Under that protocol, which is governed by the principles set forth in United States v. Mezzanatto, 513 U.S. 196 (1995), you can provide information to the government without waiving your Fifth Amendment privilege, but only if you have a skilled federal criminal defense attorney negotiating the terms of the proffer agreement.
4. Audit Your Coding and Billing Practices Against the Federal Register’s Most Recent Office of Inspector General Work Plan
The Department of Health and Human Services Office of Inspector General (OIG) publishes an annual Work Plan that identifies specific billing codes, procedures, and provider types that are under active audit. In my 25 years, I have never seen a health-care fraud case that did not involve a billing code that was flagged in the OIG Work Plan at least two years before the investigation began. You must immediately pull the most recent OIG Work Plan from the Federal Register and cross-reference it against your top 20 billing codes by volume and revenue. The OIG is currently focused on evaluation and management (E&M) coding levels, prolonged services codes (G2211 and 99417), and telehealth services provided during the COVID-19 public health emergency. If you have billed for telehealth services without a qualifying originating site or without an established patient relationship, you are at high risk.
You must also review your “incident to” billing practices under Medicare’s “incident to” provisions, which allow non-physician practitioners to bill under a physician’s National Provider Identifier (NPI) if certain supervision requirements are met. The OIG has repeatedly found that providers bill “incident to” for services that were actually performed by a physician assistant or nurse practitioner without the physician’s direct supervision, which is a violation of 42 C.F.R. § 410.26. The government treats this as a false claim because the billing provider certifies that the services were rendered in compliance with Medicare regulations. I recommend that you conduct a retrospective audit of all “incident to” claims for the last three years, and if you find errors, you should consider repaying the overpayment under the 60-day repayment rule established by the Affordable Care Act, codified at 42 U.S.C. § 1320a-7k(d).
Do not rely on your billing vendor or your clearinghouse to identify compliance issues. They are not your lawyers, and they have no duty to protect your confidences. I have seen cases where a billing vendor discovered a pattern of upcoding and reported it to the OIG’s Self-Disclosure Protocol without the provider’s knowledge, effectively triggering a government investigation. Instead, we will hire an independent certified professional coder (CPC) who is bound by a confidentiality agreement and who reports directly to our law firm. That CPC will review a statistically significant sample of your claims—at least 200 claims per provider—and will identify any patterns of overbilling, unbundling, or modifier misuse. If the CPC finds errors, we will determine whether the error rate is below the 5% threshold that the DOJ generally considers de minimis, or whether it warrants a proactive disclosure.
Finally, you must understand that the government’s experts will use “claims data analytics” to compare your billing patterns to those of your peers. The DOJ’s Unified Medical Fraud Analytics (UMFA) database contains billions of claims and can identify outliers in real time. If your practice bills for a higher volume of a specific procedure than 95% of providers in your specialty, you will receive a “pattern-based” subpoena. I have defended clients who were completely innocent of intentional fraud but who could not explain why their billing patterns deviated from the norm. The only way to survive this scrutiny is to have contemporaneous documentation—not just a chart note, but a detailed explanation of medical necessity that references the specific ICD-10 diagnosis code and the corresponding CPT code. If your documentation is lacking, you must implement a corrective action plan immediately, and you must do so under the guidance of counsel to avoid creating a “roadmap to liability.”
5. Prepare a Crisis Communication Strategy That Does Not Waive Privilege or Create an Admission
When the FBI or OIG special agents arrive at your office with a search warrant, your employees will panic. They will call their spouses, post on social media, and talk to the press. In my experience as a prosecutor, the most damaging evidence in a health-care fraud case often comes not from the search warrant itself, but from the statements that employees make to reporters, to each other, and to government agents before they have a lawyer present. You must have a written crisis communication policy that has been reviewed by federal criminal defense counsel and that instructs every employee to immediately cease all communication about the investigation and to direct all inquiries to a designated legal spokesperson. This policy must be distributed and signed by every employee this week—not next week, not after the search warrant is served.
Your crisis communication strategy must also address how you will respond to the media. The DOJ will issue a press release the moment an indictment is unsealed, and that press release will be picked up by every local news outlet. If you say nothing, the public assumes you are guilty. If you say too much, you risk making an admission that can be used against you at trial under Federal Rule of Evidence 801(d)(2), which defines a party’s own statement as non-hearsay and fully admissible. The correct approach is to issue a brief, factual statement that acknowledges the investigation, expresses confidence in the integrity of your practice, and emphasizes that you are cooperating fully with the government. You should never, under any circumstances, say “we did nothing wrong” or “the allegations are baseless” because those statements can be used to impeach you if the government later produces evidence of wrongdoing.
You must also prepare for the possibility that the government will freeze your assets under 18 U.S.C. § 1345, which allows the DOJ to seek a temporary restraining order to preserve assets that are traceable to a health-care fraud offense. I have represented physicians who had their personal bank accounts frozen and their credit cards canceled within 24 hours of a search warrant being executed. If you have significant assets, you should work with your defense counsel to create a “living trust” or other legal structure that protects your non-fraudulent assets from forfeiture. The government cannot freeze assets that are legitimately earned and that are not traceable to the alleged fraud, but you must be able to document the source of every dollar. I recommend that you immediately separate your personal finances from your practice finances and that you maintain detailed records of all withdrawals, transfers, and investments.
Finally, you must identify a qualified federal criminal defense attorney who has experience in health-care fraud litigation and who is available to take your call 24/7. Do not rely on your corporate counsel, your civil litigator, or your family lawyer. Health-care fraud is a specialized area of federal criminal law that involves complex regulatory schemes, statistical evidence, and aggressive prosecutors who have access to resources most defense attorneys cannot match. I have seen defendants who waited three days to hire a criminal defense attorney, and by that time, the government had already executed a search warrant, interviewed key employees, and frozen bank accounts. The first 72 hours after you learn of an investigation are the most critical. If you act now, you can preserve evidence, protect privilege, and position yourself for a favorable resolution. If you wait, you will be playing defense for the rest of the case.
Frequently Asked Questions
Q: If I self-disclose a billing error to the OIG, will I automatically be prosecuted?
No, but the answer depends on the nature and scope of the error. The Health Care Fraud Self-Disclosure Protocol, which is administered by the OIG, allows providers to voluntarily disclose potential fraud and receive a reduced penalty or, in some cases, a non-prosecution agreement. However, self-disclosure is not
Related Legal Resources
Related: A Healthcare Fraud Defense Lawyer Can Help You | John D. Kirby — A Healthcare Fraud Defense Lawyer Can Help You | John D. Kirby .flying-press-lazy-bg{background-image:unset!important;}
Related: Three Critical Steps to Take Today If You Face Healthcare Fraud Exposure | Kirby Law — Federal Criminal Defense — Kirbycriminallawyer Law Articles Kirby Law Three Critical Steps to Take Today If You Face Healthcare Fraud Exposure 2026
Related: Carlsbad Federal Defense Lawyer | John D. Kirby — Carlsbad Federal Defense Lawyer | John D. Kirby Law Offices of John D. Kirby About Practice Cities (619) 557-0100 Carlsb
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense